CVE-2026-73751: HPE Arubaos-Cx

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.

Affected products

  • HPE Arubaos-Cx: before 10.10.1181 (fixed in 10.10.1181); from 10.13.0000, before 10.13.1190 (fixed in 10.13.1190); from 10.16.0000, before 10.16.1060 (fixed in 10.16.1060); from 10.17.0000, before 10.17.1030 (fixed in 10.17.1030); version 10.18.0001 only

Published 2026-09-01. Last modified 2026-09-22.